I need to ignore the milliseconds when I group by _time
stats avg(instance_internal) as amount by _time, unit_id, instance_id
Because of the milliseconds there are too much entires in the end.
How do I ignore the ms ?
Try this
your base search | bucket span=1s _time |stats avg(instance_internal) as amount by _time, unit_id, instance_id
OR
your base search | eval _time=strptime(strftime(_time,"%F %T"),"%F %T")|stats avg(instance_internal) as amount by _time, unit_id, instance_id
OR
your base search | eval _time=round(_time)|stats avg(instance_internal) as amount by _time, unit_id, instance_id
Try this
your base search | bucket span=1s _time |stats avg(instance_internal) as amount by _time, unit_id, instance_id
OR
your base search | eval _time=strptime(strftime(_time,"%F %T"),"%F %T")|stats avg(instance_internal) as amount by _time, unit_id, instance_id
OR
your base search | eval _time=round(_time)|stats avg(instance_internal) as amount by _time, unit_id, instance_id
great thanks 😉 span=1m works also perfect